A Quantum Random Walk Search Algorithm 



Neil Shenvi 1 , Julia Kempe 1,2,3 , and K. Birgitta Whaley 1 
Departments of Chemistry 1 and Computer Science 2 , University of California, Berkeley, CA 94720 
3 CNRS-LRI, UMR 8623, Universite de Paris-Sud, 91405 Orsay, France 
(Dated: February 1, 2008) 

Quantum random walks on graphs have been shown to display many interesting properties, in- 
cluding exponentially fast hitting times when compared with their classical counterparts. However, 
it is still unclear how to use these novel properties to gain an algorithmic speed-up over classical 
algorithms. In this paper, we present a quantum search algorithm based on the quantum random 
walk architecture that provides such a speed-up. It will be shown that this algorithm performs an 
oracle search on a database of N items with O (x/^V) calls to the oracle, yielding a speed-up similar 
to other quantum search algorithms. It appears that the quantum random walk formulation has 
considerable flexibility, presenting interesting opportunities for development of other, possibly novel 
quantum algorithms. 



I. INTRODUCTION 



Recent studies of quantum random walks have suggested that they may display different behavior than their classical 
counterparts || |, |, One of the promising features of these quantum random walks is that they provide an 

intuitive framework on which to build novel quantum algorithms. Since many classical algorithms can be formulated 
in terms of random walks, it is hoped that some of these may be translated into quantum algorithms which run faster 
than their classical counterparts. However, previous to a very recent paper by Childs et. al. ||, there had been 
no quantum algorithms based on the random walk model. In this paper we show that a quantum search algorithm 
can be derived from a certain kind of quantum random walk. Optimal quantum search algorithms are already well 
known 0, |^, The search algorithm from a quantum random walk we present here shows some differences from 
the established search algorithms and may possess useful properties with respect to robustness to noise and ease of 
physical implementation. It also provides a new direction for design of quantum algorithms from random walks, which 
may eventually lead to entirely new algorithms. 

Current research uses two distinct models for quantum random walks, based on either discrete time steps or on 
continuous time evolution. Discrete time quantum random walks were introduced as a possible new tool for quantum 
algorithms generalizing discrete classical Markov chains Q . The discrete time walk can be thought of as a succession 
of unitary operations, each of which has a non-zero transition amplitude only between neighboring nodes of the graph. 
The relation of these to classical Markov chains provides considerable motivation for exploration of discrete random 
walks. Within the field of classical algorithms, the application of classical Markov chains in classical algorithms has 
been quite revolutionary, providing new approximation and optimization algorithms. By analogy, it might reasonably 
be hoped that similar algorithmic advances could be obtained for quantum algorithms from development of the 
quantum random walks. The second quantum random walk model is the continuous-time quantum random walk, 
introduced in 0, ^ n. In the continuous-time walk the adjacency matrix of the graph is used to construct a 
Hamiltonian which gives rise to a continuous time evolution. This model differs from the discrete time walk in that 
even for small times there is an (exponentially small) probability of transition to non-adjacent nodes. In this paper, 
we will consider the discrete-time model only. 

The paper is organized as follows. Sec. O provides a brief introduction to discrete-time quantum random walks. 
Sec. |nj describes the random walk search algorithm and provides a proof of its correctness. Sec. LV summarizes the 
similarities and differences between the random walk search algorithm and Grover's search algorithm. Conclusions 
are presented in Sec. [v|. 

Notation: Following standard computer science notation we will use the following to characterize the growth of 
certain functions: We will say f(n) — 0(g(n)) if there are positive constants c and k such that < f(n) < cg(n) for 
n > k. Similarly f(n) = fl(g(n)) if < cg(n) < f(n) for constants c, k > and n > k. 



II. BACKGROUND 



The discrete time random walk can be described by the repeated application of a unitary evolution operator U. 
This operator acts on a Hilbert space Ti c ® Ti s where TL C is the Hilbert space associated with a quantum coin and 
TL S is the Hilbert space associated with the nodes of the graph. The operator U can be written as M 



U = S-C 



(1) 
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where S is a permutation matrix which performs a controlled shift based on the state of the quantum coin, and C is 
a unitary matrix which "flips" the quantum coin. This operation can be visualized by analogy to a classical random 
walk. For each iteration of a discrete time classical random walk on a graph, a coin is flipped. The walker then moves 
to an adjacent node specified by the outcome of the coin flip. An equivalent process occurs in the quantum random 
walk, with the modification that the coin is a quantum coin and can therefore exist in a superposition of states. This 
modification can lead to dramatic differences in behavior between the classical and quantum random walks. However, 
it should be noted that if the state of the coin is measured after each flip, then the quantum random walk reverts to 
a classical random walk (and similarly if the state of the nodes is measured after every step). 

An important feature of the discrete time quantum random walk that has significance for its use in development 
of quantum algorithms, is that by virtue of its definition this walk will be efficiently implementable on a quantum 
computer whenever its classical counterpart is. (By efficient we mean that the walk can be simulated by a circuit 
with a number of gates that is polynomial in the number of bits (qubits)). This is due to the very similar structure 
of both these walks. To illustrate this, assume we have an efficient way to implement the classical random walk on 
the underlying graph, i.e. to perform the coin-flip and subsequent shift. The shift is conditional on the outcome of 
the coin-flip (which determines the direction of the next step], i.e. we have a classical efficient circuit which performs 
a controlled shift on the basis states. It is straightforward [10 to translate this circuit into a quantum circuit which 
performs the unitary controlled shift of Eq. (|l]) . Similarly if there is an efficient procedure to flip the classical coin of 
the random walk, there will be an efficient way to implement a quantum coin. Hence implementation of the discrete 
time random walk is automatically efficient if the underlying classical walk is efficiently implementable. 

Note that if no measurement is made, the quantum walk is controlled by a unitary operator rather than a stochastic 
one. This implies that there is no limiting stationary distribution fi O]. Nevertheless, several recent works have 
shown that consistent notions of mixing time can be formulated, and have shown polynomial speed up in these 
quantum mixing times relative to the classical analog |ll| . Another quantity for which quantum walks have shown 
speed-up relative to their classical analogs is the hitting time |l2], fl3"| |. Under certain conditions this speed-up can 
be exponential compared to the classical analogue. We refer the reader to the recent papers 0, |§ 5 @ and |l2| for 
some results obtained from discrete time quantum random walks. 

Our random walk search algorithm will be based on a random walk on the n-cube, i.e. the hypercube of dimension 
11, |l^]. The hypercube is a graph with N = 2™ nodes, each of which can be labelled by an n-bit binary string. 



n 



Two nodes on the hypercube described by bitstrings x and y are are connected by an edge if \x — y\ = 1, where |x| 
is the Hamming weight of x. In other words, if x and y differ by only a single bit flip, then the two corresponding 
nodes on the graph are connected. Thus, each of the 2™ nodes on the n-cube has degree n (i.e. it is connected to 
n other nodes), so the Hilbert space of the algorithm is 7i — 7i n £g> Ti 2 . Each state in TC can be described by a bit 
string x, which specifies the position on the hypercube, and a direction d, which specifies the state of the coin. The 
shift operator, S, maps a state \d, x) onto the state \d, x © e^), where €d is the d th basis vector on the hypercube. S 
can be written explicitly as, 

n-l 

S = ^2^2\d,S®e d )(d,x\ (2) 

d=0 x 

To completely specify the unitary evolution operator U, the coin operator, C, must also be chosen. Normally, the 
coin operator is chosen such that the same coin is applied to each node on the graph. This is the case in previous 
studies of discrete quantum walks on the line j|, |], [l4| and on the hypercube [[n} In other words, the coin 

operator C can be written as, 

C = Co <8> 1 (3) 

where Co is a n x n unitary operator acting on Ti c . If C is separable according to Eq. (^) then the eigenstates of U 
are simply the tensor product of the eigenstates of a (modified) coin Cg and of the Fourier modes of the hypercube 

(labelled by n-bit strings k) O], One frequently chosen separable coin is Grover's "diffusion" operator on the coin 
space, given by 

C = G = -Z + 2|s c )(s c |, (4) 

where |s c ) is the equal superposition over all n directions, i.e. \s c ) = £Li \d) @. This coin operator is 
invariant to all permutations of the n directions, so it preserves the permutation symmetry of the hypercube. The 
use of the Grover diffusion operator as a coin for the hypercube was proposed in Jll[ , where it was pointed out that 
this operator is the permutation invariant operator farthest away from the identity operator So, hcuristically, 
it should provide the most efficient mixing over states, from any given initial state. The non-trivial eigenvalues and 
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eigenvectors of U are given by [[IT] , 



2k 2i r— — 

— ± —Jk (n-k) 
n n 



(5) 



h) > \ v kT 
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\d,x) 



l/Vfc if fc d = 1 

\Jn — k if fed = 



(6) 



Note that the equal superposition over all states, |^o) = |s c ) ® | sS )> where |s s ) is the equal superposition over the 
2™ nodes, is an eigenvector of U with eigenvalue 1. So repeated application of U leaves the state |^o) unchanged. 

In order to create a search algorithm using the quantum random walk architecture, we now consider a small 
perturbation of the unitary operator U. Specifically, we consider "marking" a single arbitrary node by applying a 
special coin to that node. In this respect, the coin operator now takes on the function of an oracle. Yet, contrary to 
the standard oracle which flips the phase of the marked state in the standard setting of a search algorithm, the oracle 
acts instead by applying a marking coin, Ci, to the marked node and a different coin, Co, to the unmarked nodes. 
Without loss of generality, we can assume that the marked node corresponds to the all-zero string Xtarget — 0. Then 
our coin operator becomes 







(7) 



The marking coin, C%, can be any nx n unitary matrix. For simplicity, we will consider here the case where C\ = —T. 
Then our perturbed unitary evolution operator, U' , is given by 



U' = S-C 



= U-2S- 



s c )( S c \ 



0){Q 




(8) 



Analysis of the effects of this perturbation leads directly to the definition of the random walk search algorithm, as 
will be described in the next section. 



III. RANDOM WALK SEARCH ALGORITHM 



A. Overview of the Algorithm 



We define the search space of the algorithm to be the set of all n-bit binary strings, x = {0, 1}". We consider 
the function / (x) = {0, 1}, such that f (x) — 1 for exactly one input Xtarget- Our goal is to find Xtarget- Using the 
mapping of n-bit binary string to nodes on the hypercube, this search problem is then equivalent to searching for a 
single marked node amongst the N = 2 n nodes on the n-cube. For purposes of the proof, we have set the marked 
node to be Xtarget = 0, but the location of the marked node has no significance. 

The random walk search algorithm is implemented as follows: 

1. Initialize the quantum computer to the equal superposition over all states, |-0o) = \ sC ) ® I s " 5 )- This can be 



accomplished efficiently on the node-space by applying n single-bit Hadamard operations to the 
similar procedure works for the direction space. 

2. Given a coin oracle, C, which applies the coin Co = G to the unmarked states and the coin Cl 
marked state, apply the perturbed evolution operator, U' — S ■ C , t/ 



0) state. A 



-X to the 



= |V2" times. 



3. Measure the state of the computer in the \d,x) basis. 



It is our claim that with probability | — 0(l/n), the outcome of the measurement will be the marked state. By 
repeating the algorithm a constant number of times, we can determine the marked state with an arbitrarily small 
degree of error. In the remainder of this section we provide a proof of this algorithm. 

The general outline of the proof that we will present is the following. We need to determine the result of the 
operation (U 1 ) on the initial state \ipo}- To do this, we will first simplify the problem by showing that the perturbed 
walk on the hypercube can be collapsed to a walk on the line (Theorem (|l])). Next, by constructing two approximate 
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eigenvectors of TJ' , \i/)q) and l^i), we will show that there are exactly two eigenvalues of TJ' that are relevant (i.e. the 
initial state j^o) has high overlap with the space spanned by the corresponding eigenvectors, see Theorem (0) and 
Theorem (^)). We denote these eigenvalues by e luJ ° and e~ l "°. We will then show that the corresponding eigenvectors 
\u)' Q ) and | —Wo) can be well-approximated by linear combinations of the initial state \ipo} and the second state \tpi) 
(Theorem (||)). As a result, our random walk search algorithm can be approximated by a two-dimensional rotation in 
the \u' Q ) , |— w )-plane away from the initial state \ipo) ~ ^/V^iWo) + l — w )) and towards s» £/v2(— |w ) + \—cj' )), 
which constitutes a very close approximation to the target state \xtarget)- Finally, we show that each application 
of the evolution operator TJ' corresponds to a rotation angle of approximately l/\ / 2 n ~ 1 (Theorem (||)). Hence, the 
search is completed after approximately f V2" -1 steps, i.e., after O (y^^j cans to the oracle, where N — 2™ is the 
number of nodes. 



B. Proof of Correctness 



In general, analytic determination of the eigenspectrum of a large matrix is a daunting task, so we will take 
advantage of the symmetries inherent in TJ' to simplify the problem. Let us first show that the perturbed random 
walk on the hypercube can be collapsed onto a random walk on the line. Let Py be the permutation operator which 
swaps the bits i and j, in both the node space and the coin space. In other words, given a state \d,x), under the 
permutation operator, Py, the i th and j bits of x are swapped and the directions d = i and d = j are swapped. 
Clearly the unperturbed evolution operator TJ commutes with Py since every direction in the unperturbed walk is 
equivalent. 



Theorem 1 TJ' commutes with P^ . 



Proof. 



P T TP P 



TJ P 



2P} j S- 

= u-^X^Pl^^idMP, 

= TJ' 



(\.s c )(s c \® |o) (o|) 



(9) 



So, [U',Pij] = 0. | 

Because the initial state \ipo) is an eigenvector of Py with eigenvalue 1 for all i and j, and [U',Pij] = 0, 
any intermediate state \tpt) = (U'Y |"0o) must also be an eigenvector of eigenvalue 1 with respect to Pij. Thus, 
(U'Y preserves the symmetry of l^o) with respect to bit swaps. It is therefore useful to define 2n basis states, 



|P,0),|L,1),|P,1) 



\R, n — 1) , \L, n) where 



\R,x) 



\L,x) 



(»-*)0 i 



i E E 



(10) 

(11) 



which are also invariant to bit swaps Pij. These states span the eigenspace of eigenvalue 1 of Pij. Using these 
basis states, we can project out all but one spatial degree of freedom and effectively reduce the random walk on the 
hypercube to a random walk on the line. This is illustrated in Fig. |l|. The marked node corresponds now to \R, 0). 
We can rewrite TJ, TJ', and \ipo) in this collapsed basis. First note that the shift operator S in this basis acts as 



S = J2 \ R > x ) ( L ' x + 1 1 + x + i) : 



x=0 



and the unperturbed coin acts as 



(12) 



co = E 



cos uj x sm oj x 



sin uj x 



cos uj x 



® |x) (x\ 



(13) 
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where cos lu x = 1 — ^ and s'm uj x = —\fx (n — x) and where the first part acts on the space spanned by {\R) , \L)} 
and the second part acts on the positions {|0) , . . . , \n)} on the line. Note that the coin of the collapsed walk is not 
homogeneous in space any more. The unitary operator U on the restricted space acts as 

U = J2xZo \ R ' X ) (~ cosuj x+1 (L,x + 1| + sinw^+i (R,x + 1|)+ 
Ex=i \ L ' X ) (sino; x _i (L,x- 1| + cosw x _i (R,x- 1|) 

Similarly, 

U' = U + AU = U — 2\L,l) (R, 0| (15) 
Note that the only difference between {/ and {/' is in the sign of the matrix element in position (|£, 1) , \R, 0)). Finally, 



|^o) = -= 0) + -= \L, n) + V h ^ |L, x) + \ ^ x) (16) 





Since f and Py are mutually diagonalizable, the eigenvectors of U in the reduced space are also bit-flip invariant. 
Examining Eq. (^|), it is clear that if we take the equal superpositions of all eigenvectors of same eigenvalue such 



that 



= k, the resulting eigenvector will be bit-swap invariant. Thus we define, 

1 



V (fe) |fc|=fc 

which are the eigenvectors of U with eigenvalues e luJk in the collapsed (symmetric) space. 

Note that both U and U' are represented by real matrices; therefore, their eigenvalues and eigenvectors will come 
in complex conjugate pairs. 

Having determined these general properties of the perturbed matrix U' , we now turn to the problem of analyzing 
the eigenvalue spectrum of U' . Let A be the arc on the unit circle containing all complex numbers of unit norm with 
real part greater than 1 — 2/3n. In other words, 

„4={z|Rez>l-|-,|z| = lJ (18) 

Fig. H shows the geometrical representation of A together with the eigenvalue spectra of the unperturbed and perturbed 
matrices for n = 8. We will prove that A contains exactly two eigenvalues e lu ° and e~ l "° of U' . First, we will prove 
that there are at most two eigenvalues with real part greater than 1 — 2/3n. Then we will show that there are at least 
two eigenvalues on A. From these facts, it follows that there are exactly two eigenvalues of U' on A. 

Theorem 2 There are at most two eigenvalues of U' with real part greater than 1 — 2/3n. 

Proof. We will prove by contradiction. Let us assume that there are three eigenvalues, e lul °,e luJl , and e*" 2 , with real 
part greater than 1 — 2/3n. Let \lo' ), and \ui' 2 ) be the corresponding eigenvectors. Then, 



> 3-2/n 



(19) 



Let us define fl to be the subspace spanned by |cl>q), \u>{}, \u)' 2 ). Then we can write Eq. ( |l9| ) as the partial trace of U' 
over f2, 

Re Trnt/' > 3-2/n (20) 

Let us now define |^>_) = (|0, R) — We can expand the |cJq), Wi), and in terms of \ipo), \ip-) and a 

residual vector, 

H) = c oolV^o)+^ 1 |V'-)+^ 2 |r; ) ) 

l^x) = c 'io IV'o) + c'n 1^-) + c'n \r'x) 

l^> - 4olV'o) + 4 1 |V-) + 42K) (2i) 
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where \r[) is a normalized vector orthogonal to \4>o) and \ip~). We now observe that, due to the basis invariance of the 
trace, Eq. ( po| ) holds for any linear combination of \ui' ), \^[), and \u) 2 ). Thus, we can construct three new orthonormal 
vectors, |ao), and |a 2 ) by taking linear combinations of \u>' ), \u)[), and \u> 2 ) such that, 

(« 2 |Vo) = <a 2 |lM = (22) 
In other words, we can expand \cxq), \oti), and |a 2 ) as, 

|ao> = c 00 |-0o) +coi \ip-) +c 2 |r ) 

|«i> = ciojVo) +c n \il>-) +ca\ri) (23) 
«2> = k 2 ) 



Since |ao), lai), and |a 2 ) still form a basis for 17, from Eq. ( J20| ) it follows that, 

3-2/ti < Re E<Oil^'l«i) (24) 

Since [/' is a unitary operator, we know that Re (aj| J7' |aj) < 1 for all \ai). Thus, applying this inequality to the 
first two terms in the sum, we obtain, 

Re («<l ^ l«<) < 2 + Re (a 2 | [/' |a 2 > (25) 

i 

Since, U' — U + AU, we can write 

Re (a 2 \U'\a 2 ) = Re (a 2 \ U \a 2 ) + Re (a 2 |AC/|a 2 ) (26) 
Let us first consider (a 2 | 17 |a 2 ). We can expand |a 2 ) in terms of the unperturbed eigenstates, |a 2 ) = ■ &j l^j)- So, 



Re (a 2 \ U \a 2 ) — \bj\ cosw,-. However, since (a! 2 |V>o) = 0, there is no contribution from the eigenvalue with value 
1. The eigenvalue with the next- largest real part is e lu)1 = 1 — 2/n + i\\/fi — 1. Thus, 

Re (a 2 \U\a 2 ) < 1 - 2/n (27) 

Next, we consider, (a 2 | At/ |a 2 ). Let \ip + ) — (|0, R) + |1, L)). Using Eq. ( [l5|) we can express AJ7 in terms of |^_) 
and \ip + ), 

AU = |^_) ftM + |^_) (V+| - W+) - |V+> (V+l (28) 
But since (a 2 |^-) = (see Eq. @), 

(a 2 |A*7|a 2 ) = (-|(^+|a 2 )| 2 ) <0 (29) 



Then, Re (a 2 \ U' |a 2 ) < 1 - 2/n. Combining Eq. Eq. @, and Eq. @, we obtain, 

Re ^(oilt/'loi) < 3 -2/n . (30) 

Since this contradicts Eq. (p4|), our assumption must be false. | 
Theorem 3 There are at least two eigenvalues of U' on A. 



Proof. We will construct two approximate eigenvectors of U' , \ipo) and \ipo) is given by Eq. (|16[). Using Eq. (|15|), 

C/'|Vo) = |Vo)-2/^|L,l) (31) 

And, 

(Vol^'M*) = (^olV'o) - <Vo]i, 1} 0|^ > 



1 - 1/2 



„-i (32) 
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So, apart from a small residual, |?/>o) is also "almost" an eigenvector of U' with eigenvalue 1. Now, we need to find a 
second approximate eigenvector, l^i)- Let 



/n/a-i \ 
l^)= E / , i^^)- / 1 \L,x + l)\/c (33) 



where c is a normalization constant, 



n/2-l 

\ E T^TT ( 34 ) 



=0 V a: 



Using this definition and Eq. Jl4|), we see that 



U' | Vi) = |Vi) ^=^= (\R, n/2 - 1) + |L, n/2 + 1)) (35) 



So, 



(^It / 'I^> = 1-7^77^TT (36) 

ZC Vn/2/ 

It is straightforward to show that 1 < c 2 < 1 + 2/n for sufficiently large n. Thus, except for a small residual, \ifji) is 
"almost" an eigenvector of U' with eigenvalue 1. 

Now let us verify that there is at least one eigenvalue of V on A. Let us assume that there are no eigenvalues of 
U' on A. Then coso^ < 1 - 2/3rc for all j. Then using Eq. @, 



1 - 1/2— 1 = Re ^o|C/'|^o) 

(37) 



< (l-2/3n)E|(VtoK>| 
i 

= 1 - 2/3n 

which is wrong for n > 3. Hence our assumption is false and there must be at least one eigenvalue of U' on A. 
Now let us assume there is exactly one eigenvalue of U', e luJ °, on A. Then, 

1- 2^r = Re (ip \U'\<pa) 

= E 7 |\^oK>| cos a/ 

2 2 f 38) 

= KV>oK)| COSUJ +Ej^0 |(^o|Wj->| cost^ 1 j 

< |^ K)| 2 +(l-|^oK)| 2 )(l-2/3n) 

Rearranging terms, 

|(^oK)| 2 >l-^ (39) 
If we use as a trial vector and follow the same arguments, we obtain the inequality 

m^f^-^y (4», 

But since |"0o) and \ipi) are orthonormal, this leads to a contradiction, since, 

i = kk) 

> |(^K)| 2 + |^iK)| 2 ( 4i) 
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which is not true for large n. Hence, there must be at least two eigenvalues on the arc A. I 

As noted above, the eigenvalues and eigenvectors of U' come in complex conjugate pairs. In particular the two 
eigenvalues on A must be a complex conjugate pair; let e ±luJ ° be the two eigenvalues on A. The corresponding 
eigenvectors obey |— u>' Q ) = \uj' ) (if e luJ « = e _tw <> = 1, then we can construct linear combinations of \uj' ) and \—u>' ) 
for which this statement is true). We will now show that |±^q) can be well-approximated by linear combinations of 
|V>o) and \ipi). 

Theorem 4 



Wo) = Vpo \i>o) + VPi^ IV>i) + V 1 - Po - Pi \ro) 
\-co' Q ) = |Vo) + y/pie^ lV>i> + VI - Po ~ Pi \ro)* (42) 

where po — \(u! \i/jq)\ 2 = \(—uj \iPq)\ 2 , p\ — \(ui' \ipi)\ = | (— di \tpi) | 2 and \ro) is a normalized vector orthogonal to 
\i/) ) and l^i). Furthermore, 1/2 > p > 1/2 - 3n/2 n+1 and 1/2 > pi > 1/2 J^ty, with e ir > = i + A, where 

\a\ = o / 



nc 

Using Eq. (|32j) 



Proof. Since \ipo) and \tpi) are real vectors, |(wg|i/'o)| 2 = I (~ ^-'olV'o) | 2 < 1/2 and | (c^q | 2 = | (— ui'q\iPi) | 2 < 1/2. 



= Re (MU'^o) 

= 2p cos uj' + Y,j^o COSLJ 'j l ( w j#o)| 
< 2p + (1 - 2/3n) (1 - 2 Po ) 



(43) 



Rearranging terms, we obtain, 



3r> 

p >l/2-^, (44) 



Using Eq. (pq) and the same arguments as above we obtain 



3n 

Pi > 1/2 ; — r— . (45) 

8c 2 (;7 2 x ) 



Up to a global phase can be written as, 



K) = |K|^o)| |^o) + IKIV'Ole 4 " +V 1 ~Po-Pi\ro) (46) 



which yields Eq. (42) for \u' ) and |— ui ). 

To estimate e 1 ' 7 note that since \u)' ) and |— uj' ) are eigenvectors of a unitary matrix, they must be orthogonal. 
Consequently, 



Solving for e lv , we obtain, 



o = WW (47) 



Re (e"') 2 = -PQ-^-^-P^^Iro) (4g) 

Pi 



Assume Re (r^ \ro) > 0. Then, using 1/(1 — x) < 1 + 2x for small x we get 

2™ " Pi 



Po 

> Re (e 1 ") 2 > 



3n | 3n 



pi 
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which in turn implies that e lri = i + A with | A| = O y ^-i) j • A similar reasoning holds if Re (r^ |ro) < 0. I 
As a last ingredient we need to bound the angle u' Q . These bounds are provided in the following final theorem. 



Theorem 5 



^=T-/3<^<-^=r+/3, where /3 = 0(*g.) 



Proof. We will approximate e luJ 'o = (uj' \ U' \u' ) by (a\U'\a), where |a) = l/\/2 (|^ ) + |"0i))- Let us first 



evaluate 



e iuJ ° — (a\ U' | a) ■ We can expand U' in terms of its eigenvectors to obtain, 



e*"° - (a\U'\a) 



^-El(m«)l 2 ^ 



We then note that from Eq. 



So, 



e ^o _ (q,| [/' | a ) 



< 



e-o _ ( v /^72 + ^72) e -o + £ |(a/|a)| 2 e M 

KM"*) 



(50) 



(51) 



(52) 



< 2 



< 2 



3n 



2 " +1 ^ ^7?) 



with a/1 — £ > 1 — a; for < a; < 1. Using the fact that the binomial coefficients approach the Gaussian distribution 
for large n, such that, 



xl V nn 



we can rewrite Eq. ( p2[ ) taking the leading order terms in n. Recalling that c > 1, we obtain, 



e «-o -( a \U'\a) 



= O 



(53) 



(54) 



Eq. (^4|) is an explicit formula which bounds the distance in the complex plane between the eigenvalue of interest, 
e luJ °, and the matrix element (a\ U' \a). Fig. || shows the geometric representation of Eq. (jEJ). Note that, 



\smv' - Im (a\ U' \a)\ = Im (e^° - (a\ U' |a)) < - (a\ U' \a) 



(55) 



Next, we evaluate Im (a\ U' \a) using Eqs. ( |3l| ) and (|35), 

Im (a\ U' \a) = Im (e*» (Vol 17' |^) - <-0i | 17' |^» 

m>\R,n/2 - 1) + + 1» ~ e»' (-* {fa\L, 1)) 

C V 2 ("/2J V V 1 



Im| 



(56) 



-Im 



CV2"- 1 CV2"- 1 

Then, using Theorem (Q), Eq. (p4]), and Eq. (|5^) we can write 

1 Q ( n 



J ri ' ; 

cx/2^1 



mil). 



o 



3/2 
1 ' 

2" 



(57) 
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Using sin a; = x + 0(x 3 ) and keeping only leading order terms solving for uj' gives us, 



' -o(^)<u' <-^= + o(^). | ,r,s, 



We can now quantitatively describe the overall operation of the algorithm. Starting with initial state we 
consider the state of the computer after t applications of U' . Then using Theorem ([|) we can expand |-0o) as 

\^) = Vm(H) + \-^'o)) + S\r) (59) 



where 5 = VI — 2po = 0(^/n/2 n ) and |r) is a residual normalized vector orthogonal to \oj' ) and |— uj' ). Now 

(U'f\ipo) = V^( e ^*K) +e-^ t |-^o» + <5k') 

= 2 Po cosuj' t |V> ) - 2^pT(sin^t + Re e ia, °* A) |-0i> 

+ VI - Po - Pi^' \r Q ) + e-^'o* \r*)) + S \r) [bU > 

= cosw^l^o) -sin4i|^i) + 0(^)|f) 

where |f) is some residual normalized vector (not necessarily orthogonal to |^o) and l^i)) ■ 

Starting with | "0o) aud applying U' for tf = —r-n steps, we approximately rotate from l^o) to IV'i)- From we 



can obtain \xtarget) = 0y with high probability p, since from Eq. ( |33| ) and with 1 + l/2n < c < 1 + 2/n for large n 

v = ^EJ^oi^l^iK^oi^)! 2 

>I^^-0(l/n) ( 61 ) 
Finally, to obtain tf in terms of n, we make use of the bounds on u>' provided by Theorem ([5]): 

7.3/2 



t, = ^V2^(l±0(^=)) 



V2^(l + 0(-)) (62) 
2 n 



If we set the number of time steps to be tf — ^ V2™ 1 (or the closest integer) then 



sin^t/ = sin £(1 - O(-)) - 1 - O(^). (63) 
2 n n z 



So the probability to measure \x ta rget) after = |V2 n_1 steps is still p SUC cess =1/2— 0(l/n). Hence, by repeating 
the algorithm a constant number of times, the probability of error can be made arbitrarily small. Note the periodic 
nature of the evolution under U' (Eq. (|60|)); this means that if we measure at t > tf the probability of success will 
decrease and later increase again. 

In summary we arrived at the final result that the marked state is identified after 0{-\fN) calls to the oracle. 



IV. CONNECTION TO GROVER'S ALGORITHM 



The operation of the random walk search algorithm is similar in many ways to the operation of Grover's search 
algorithm. Both algorithms begin in the equal superposition state over all bit strings. Both algorithms make use 
of the Grover diffusion operator, G, (sometimes known as the Grover iterate). Both algorithms can be viewed as a 
rotation in a two-dimensional subspace. Both algorithms use an oracle which marks the target state with a phase 

of —1. Both algorithms have a running time of O (v^/v) • In both algorithms we have to measure at a specific time 

to obtain maximum probability of success. However, there are several important differences between the two search 
algorithms. In this section, we call attention to the ways in which the random walk search algorithm is distinct from 
Grover's algorithm and consider how these differences affect performance and implementation. 

It is well-known that Grover's algorithm can be mapped exactly onto a rotation in the two-dimensional subspace 
spanned by the equal-superposition state IV'o) and the marked state |0) [Q. Each iteration in Grover's algorithm 
corresponds to a rotation in this subspace. In this paper, we have shown that the random walk search algorithm 
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can also be viewed as a rotation in a two-dimensional subspace. However, there are two important distinctions. 
First, the random walk search algorithm can only be approximately mapped onto a two-dimensional subspace. Unlike 
Grover's algorithm, this mapping is not exact. Second, the two-dimensional subspace in which the random walk search 
algorithm is approximately contained is spanned by |^o) and l^i); n °t by \ipo) and |0). Hence, the final state of the 
algorithm is not exactly the pure marked state, |0), as it is in Grover's algorithm. It is a linear combination of states 
which is composed primarily of the marked state, but also possesses small contributions from its nearest neighbors, 
second-nearest neighbors, etc. Thus, the random walk search algorithm contains traces of the underlying topology of 
the hypercube on which it is based. 

Another difference between the two algorithms is their use of the Grover diffusion operator, G. In Grover's algorithm, 
this operator is applied to the entire 2™-dimensional search space (corresponding to the node space in the random walk 
search algorithm). On the other hand, Grover's diffusion operator, G, in the random walk algorithm is used as the 
quantum coin, and acts only on the n-dimensional coin space. This fact may be of practical use for certain physical 
implementations since many physical implementations of quantum computers contain multiple types of qubits, which 
have different natural gate sets. We could exploit this variety using the random walk search algorithm by choosing 
the coin space to be represented by qubits on which it is convenient to implement the Grover diffusion operator. 

Another similarity between the two algorithms is the implementation of the oracle. In Grover's algorithm, the 
oracle marks the target state with a phase of —1. To arrive at this random walk search algorithm, we chose the 
marking coin C\ to be the —X coin. This choice was actually motivated because it yielded a result that was amenable 
to analysis, and while the emergence of Grovers algorithm appears natural in hindsight, it was not obvious at the 
outset. However, more generally, it is not clear whether this choice of marked coin is either optimal or unique. In 
fact, numerical simulations have shown us that many different types of marking coins will yield search algorithms. 
Unfortunately, analytic treatment of the quantum random walk for more complicated coins has proven substantially 
more difficult than the instance analyzed here for G\ = —X. It is an open question what (constant factor) gains might 
be made by using different marking coins to implement the search. 

V. CONCLUSIONS 

In this paper, we have shown that the random walk search algorithm can search a list of 2™ items in time proportional 
to v2™- The lower bound on a quantum search of an iV-item list is known to be f2 Thus, up to a constant 

factor, the random walk search algorithm is optimal. However, although after repetition of the algorithm a constant 
number of times the result is arbitrarily close to the result of Grover's search, the random walk search algorithm is 
not identically equivalent to Grover's algorithm. In particular, the final solution obtained by the random walk search 
still retains some of the underlying character of the hypercube on which it was based, with a small admixture of states 
other than the solution at the marked node. 

The random walk search analyzed here was based on a discrete walk on the hypercube. In general a similar 
methodology can be applied to any regular graph, e.g., a two-dimensional hexagonal lattice with periodic boundary 
conditions, a three-dimensional rectangular lattice with periodic boundary conditions, etc. We have numerical evidence 
indicating that this methodology will yield quantum search algorithms when applied to other regular n-dimensional 
lattices. Future studies will investigate the extent of optimality of such search algorithms. 

The intriguing possibility of finding novel algorithms based on the random walk also remains an open question. 
The results described here indicate that the random walk search algorithm provides a suggestive framework for new 
algorithms. Though the optimality of Grover's algorithm precludes the construction of an improved oracle-based 
search algorithm based on a quantum walk, nevertheless, many other oracle problems still exist for which a quantum 
walk may be advantageous. For instance, the lower bound on quantum search holds only for oracles which provide 
"yes/no" information |)). Our choice of marking coin here has a clear relation to an identifiable component of Grover's 
algorithm. In general, the marking coin can be an arbitrary nxn unitary matrix. The marking coin provides a intuitive 
means by which to introduce a large amount of information to an oracle problem. Thus, it is possible that unique 
coins with interesting properties may give rise to an entirely new algorithm. Overall we conclude that the quantum 
random walk provides a means for insight into existing quantum algorithms and offers a potentially vast source for 
development of new algorithms. 
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FIG. 1: Collapsing a random walk on the hypercube to a random walk on the line. States on the hypercube are mapped to 
state on the line based on their Hamming weight and the direction in which they point (see text). 

Acknowledgments 

NS thanks the University of California, Berkeley, for a Berkeley Fellowship. This effort is sponsored by the Defense 
Advanced Research Projects Agency (DARPA) and the Air Force Laboratory, Air Force Material Command, USAF, 
under agreement number F30602-01-2- 0524. We also thank NSF ITR/SY award 0121555. 



[1] 
[2] 

[3, 

[4] 
[5] 
[6] 
[7] 

[s; 

[9 
[10 

[11 
[12 

[13 
[14 



Y. Aharonov, L. Davidovich, and N. Zagury, Phys. Rev. A 48, 1687 (1993). 

D. Aharonov, A. Ambainis, J. Kempe, and U. Vazirani, in Pro ceedings of ACM S ymposium on Theory of Computing 
(STOC) (ACM, New York, NY, 2001), pp. 50-59, LANL preprint |quant-ph/0012090j . 

A. Ambainis, E. Back, A. Nayak, A. Vishwanath, and J. Watrous, in Proc. 33rd STOC (ACM, New York, NY, 2001), pp. 
60-69. 

E. Farhi and S. Gutmann, Phys. Rev. A 58, 915 (1998). 

A. Childs, E. Farhi, and S. Gutmann, quant-ph/0103020 (2001). 

A. Childs, R. Cleve, E. Deotto, E. Farhi, S. Gutmann, and D. Spielman, quant-ph/0209131 (2002). 

L. Grover, in Proc. 28 th Annual ACM Symposium on the Theory of Computation (ACM Press, New York, NY, 1996), pp. 
212-219. 

L. Grover, Phys. Rev. Lett. 79, 325 (1997). 

C. Bennett, E. Bernstein, G. Brassard, and U. Vazirani, SIAM J. Comput. 26, 1510 (1997). 

M. Nielsen and I. Chuang, Quantum Computation and Quantum Information (Cambridge University Press, Cambridge, 
2000). 



C. Moore and A. Russell, Proc. RANDOM, to appear (2002), lanl-arXive biiant-ph/0104137 
J. Kempe, quant-ph/0205083 (2002). 

T. Yamasaki, H. Kobayashi, and H. Imai, quant-ph/0205045 (2002). 
J. Watrous, Journal of Computer and System Sciences 62, 376 (2001). 



13 



• — i — l — i — l — i — l — i — l — i- 



A 



H 1 1 1 1 1 1 1 1 £ 




FIG. 3: Geometric representation of Theorem (|^), which proves that the eigenvalue, e l "°, must be located on a disc of radius 



rr centered at (a\ U' \ a). The position of the eigenvalue is denoted by a cross. 



